There is a vulnerability with `semver` < `7.5.2`: https://github.com/advisories/GHSA-c2qf-rxjj-qqgw The solution is to upgrade `semver` to `7.5.3` which includes a patch to fix the vulnerability.